# A receipt for every Salesforce deploy, ready for any auditor.

> A SyncOnAI 360 deploy receipt is the record of one deploy to a Salesforce org: the components changed, the request or prompt that produced them, the pre-flight checks and their results, the approver and the time, and the recorded previous version used for rollback. Workspace actions are kept in a separate activity log.

Source: https://synconai360.com/features/deploy-receipts

## Key facts

- **Every**: Deploy has a receipt
- **5**: Facts per receipt: change, request, checks, approver, time
- **1**: Click from receipt to rollback
- **4**: Activity log filters: deploys, logins, settings, scans

## Why "who deployed that on Friday?" is so hard to answer

Salesforce shows that a deployment happened. It does not tell you why, who asked for it, what was checked, who approved it, or what the components looked like before. That context lives in chat threads and memories.

- **No reason recorded.** The deploy log shows components, not the request or ticket behind them.
- **No approval evidence.** Who signed off is buried in a message, if anyone did.
- **AI-built changes untraceable.** When AI writes the change, nobody can later say which prompt produced it.
- **Post-mortems start from scratch.** Every incident review begins by reconstructing what shipped.

## What is recorded on a Salesforce deploy receipt?

What changed, the prompt or request that produced it, the pre-flight checks and their results, who approved it and when. Open a receipt from Deploys or from the org it changed.

Because the request is recorded, a change the AI built can always be traced back to what was asked for, which is the question that matters most when reviewing AI-assisted delivery.

- Components changed
- The request or prompt behind them
- Checks and results
- Approver and time

## How does a receipt support rollback?

Each receipt keeps the version of every component recorded before the deploy. Roll back from the receipt and those versions are redeployed. Rolling back production needs an admin, and a deploy can only have one rollback in progress.

Components the deploy created are not deleted by a rollback; they are removed separately, so a rollback never deletes something it cannot be sure about.

- Previous version recorded
- Rollback from the receipt
- Created components removed separately

## What does the workspace activity log add?

The activity log records who did what across the workspace: deploys started, succeeded or failed, org metadata refreshes, settings changes such as an AI key or team change, and org connections, with filters for each.

Every call an external AI client makes through the MCP connection is logged too, with the tool and token it used. The log covers privileged actions rather than every read, and says so.

- Deploys, refreshes, settings and connections
- External AI client calls
- Filterable

## How do receipts connect to the rest of the work?

Work items on project boards link to the proposals and deploys that delivered them, so a release report can point at receipts rather than card movements. Components deployed are read back into the repository immediately after a successful deploy.

The audit flags production changes made outside the pipeline, so changes without a receipt stand out instead of blending in.

- Work items linked to receipts
- Deployed components read back
- Changes without receipts flagged

## How do receipts help with AI-assisted delivery?

When AI drafts changes, the question reviewers ask is what was requested and whether the result matches it. The receipt answers both: the request that produced the change sits next to the files that changed and the checks they passed.

That makes AI-built work reviewable after the fact, by an auditor, a client or a new team member, without relying on anyone's memory of the conversation.

- Request beside the result
- Reviewable after the fact by anyone

## How a receipt is created

1. **Request.** A change is asked for in chat, a builder or by a teammate.
2. **Check and approve.** Pre-flight checks run; an admin approves production.
3. **Deploy.** The deploy runs and the previous version is recorded.
4. **Receipt.** Change, request, checks, approver and time are written.

## Deployment records, with and without receipts

| Without | With SyncOnAI 360 |
|---|---|
| A list of deployed components | Components, request, checks, approver and time |
| No idea which prompt built it | The request behind every AI-built change |
| Approval in a chat thread | The approver named on the receipt |
| Rollback from memory | Rollback from the recorded version |
| Side-door changes blend in | Changes outside the pipeline flagged |

## Who uses deploy receipts

- **Auditors and compliance teams.** Answer who approved a change, what it contained and what was asked for from one receipt per deploy, without assembling evidence from tickets and emails.
- **Salesforce admins.** Open any deploy from Deploys or from the org it changed and see exactly what went in, the checks it passed and the version it can be rolled back to.
- **Consultancies.** Hand a client a record of every change delivered, linked to the work items it closed, so delivery reports point at evidence rather than card movements.
- **AI governance leads.** Trace every AI-built change back to the request that produced it, and every call an external AI client made through the MCP connection, with the tool and token used.
- **Delivery leads.** Point release notes and status reports at receipts, so each claim about what shipped links to the record of the deploy that shipped it.
- **Salesforce developers.** See exactly what your change contained when it deployed and what it replaced, which makes a regression quicker to trace and the right fix quicker to propose.

## Frequently asked questions

### What is a deploy receipt?

The record of one deploy: what changed, the request behind it, the checks, the approver and the time, plus the previous version for rollback.

### Does it record AI prompts?

Yes. The prompt or request that produced a change is recorded on the receipt.

### Where do I find receipts?

From Deploys, or from the org the deploy changed.

### Can we roll back from a receipt?

Yes. Roll back redeploys the version of each component recorded before the deploy.

### Is there a log of other workspace actions?

Yes. The activity log records deploys, org refreshes, settings changes and connections, plus external AI client calls.

### Does the log record every read?

No. It records privileged activity rather than every read, and the Trust Center says so.

### Can receipts help with SOX or similar audits?

They provide the change evidence auditors typically ask for: what, why, checks, approver and time. They do not certify compliance on their own.

### Are receipts on every plan?

Yes. Every plan includes every feature.
